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DETAILED ACTION 

Claim Rejections - 35 USC §102 
The following is a quotation of the appropriate paragraphs of 35 U.S. C. 102 that form the 
basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public use or on 
sale in this country, more than one year prior to the date of application for patent in the United States. 

Claims 1-18 are rejected under 35 U.S.C. 102(b) as being anticipated by Pereira 
(5,809,230). 

As per claim 1 Pereira teaches the use of a method of dynamically checking a resource control 
associated with newly added software to an operating system, the method comprising: 

encountering the newly added software and the associated resource control by an entity in the 
operating system (col. 7 lines 19-49) ('After the access control program is installed, the program 
requests the user to register as the Primary User and to identify a password. This password is 
used to identify the Primary User at subsequent logins. After installation of the program and 
registration of the Primary User, only the Primary User may thereafter install software on the PC, 
upgrade the access control program or uninstall the access program.'); 
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determining whether a resource associated with the resource control is active (col. 7 lines 19-49) 
(Tart of the installation procedure is to insert commands into a system initialization file, such as 
the AUTOEXEC.BAT file, before the command which activates an operating system or 
Windows interface program.'); 

determining whether usage of the resource by the entity exceeds a limiting value stored in the 
resource control, wherein one or more actions are triggered if the limiting value is exceeded (col. 
10 lines 10-47) ('The access control program may also include a function for limiting a user's 
access to a computer resource to a particular time period. 5 ); 

granting the resource to the entity if the limiting value has not been exceeded (col. 7 lines 49-67) 
('In response to the closing of the manage users function, the access control program generates a 
file of authorized user identifiers and, as each user supplies a password, the file is updated with 
each user's corresponding password. This file is used by the access control program to limit 
access to the system to authorized users only'); 

resetting the limiting value of the resource control to another threshold value (col. 10 line 34- 
col. 1 1 line 30) ('In response to a detected change, the program component resets the system so 
that all three program components are reloaded from the hard disk to memory to overwrite the 
changed program component.') 
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wherein the entity has an arbitrary number of limiting values associated with the resource control 
(col. 10 lines 10-47) ('The access control program may also include a function for limiting a 
user's access to a computer resource to a particular time period.') 

As per claim 2, Pereira teaches a method further comprising the entity searching a first set of 
resource controls to locate the resource control (col. 10 line 34 - col. 1 1 line 10) ('One program 
component is loaded resident in memory to, preferably, allocate memory space for a user and 
monitor memory access. This program allocates memory for a user and verifies that the 
attempted memory access is for a memory location in a memory space authorized for the user.') 

As per claim 3, Pereira teaches a method further comprising the entity searching a second set of 
resource controls associated with a plurality of entities to locate the resource control (col 10 line 
34 - col. 1 1 line 10) ('The second program component loaded into memory preferably monitors 
operating system and/or Windows calls to verify whether the requested resource is authorized for 
access by the user.') 

As per claim 4, Pereira teaches a method further comprising determining whether a resource 
associated with the resource control is active (col. 7 lines 19-49) ('Part of the installation 
procedure is to insert commands into a system initialization file, such as the AUTOEXEC.BAT 
file, before the command which activates an operating system or Windows interface program.'); 
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As per claim 5, Pereira teaches a method further comprising loading the resource control from a 
global set of controls to a local set of controls associated with the entity. 

As per claim 6, Pereira teaches a method further comprising notifying a plurality of other entities 
when there is a violation of a limiting value by the entity (col. 10 lines 10-47) ('The access 
control program may also include a function for limiting a user's access to a computer resource 
to a particular time period.'). 

As per claim 7, Pereira teaches a method wherein an entity is one of a process, task, and a project 
in the operating system (col. 7 lines 19-49) ('After the access control program is installed, the 
program requests the user to register as the Primary User and to identify a password. This 
password is used to identify the Primary User at subsequent logins. After installation of the 
program and registration of the Primary User, only the Primary User may thereafter install 
software on the PC, upgrade the access control program or uninstall the access program.' 

As per claim 8, Pereira teaches a method wherein encountering the newly added software and the 
associated resource control by an entity in the operating system further includes registering the 
resource controls associated with the newly added software with the operating system (col. 7 
lines 19-49) ('After the access control program is installed, the program requests the user to 
register as the Primary User and to identify a password. This password is used to identify the 
Primary User at subsequent logins. After installation of the program and registration of the 



Application/Control Number: 09/785,022 Page 6 

Art Unit: 2127 

Primary User, only the Primary User may thereafter install software on the PC, upgrade the 
access control program or uninstall the access program.') 

As per claim 9, Pereira teaches a method I further comprising manually changing the limiting 
value as desired (col. 8 line 52- col. 9 line 43) ('While access to the other directories in the 
restricted list are completely restricted, the status of these directories may be changed by the 
Primary User. 5 ) 

Claims 10-12 are rejected based on the same rejections of claim 1. 



As per claim 13, Pereira teaches a method for dynamically adding a resource to an operating 
system wherein the resource has a variable number of limits comprising: 

executing a process request for a resource that has a plurality of control values and searching in a 
local set of resources corresponding to the entity (col. 12 lines 13-59) (If the hard disk protection 
program is not installed, system initialization continues with the loading of the operating system 
and the program components of the access control program, however, the protection provided by 
the hard disk protection program is not available. Control is then transferred to the operating 
system. Thereafter, the access control program intercepts interrupt service calls and verifies 
whether the user is authorized to access the requested resource.'), 
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determining whether a usage value is greater than a control value from the local set (col. 10 lines 
10-47) ('The access control program may also include a function for limiting a user's access to a 
computer resource to a particular time period.'); 

and determining whether a user has a privilege status for the resource (col. 10 lines 10-47) ('The 
access control program may also include a function for limiting a user's access to a computer 
resource to a particular time period.'). 

As per claim 14, Pereira teaches a method further comprising: 

where the usage value is greater than a control value from the local set, approving the grant of 
the resource control and where the usage value is less than the control value, making a further 
determination as to whether the action is contained within a global set (col. 10 lines 10-47) ('The 
access control program may also include a function for limiting a user's access to a computer 
resource to a particular time period.'). 

As per claim 15, Pereira teaches a method further comprising: 

denying the resource to the requesting party where the action is not global, and setting the 
resource control to the next lowest action where the action is determined to be contained within a 
global set ('This program controls access to system resources during the remainder of system 
initialization and loads the operating system and program components for the access control 
program. Control is transferred to the operating system and the program components of the 
access control program limit user access to the resources identified in restricted lists as set forth 
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above. If a user attempts to boot the system with a boot program stored on media or a diskette 
drive, the boot program tries to use the hard disk interrupt to look at the master boot record. In 
this case, the program is unable to gain sufficient information to search the hard disk and load the 
operating system. If the hard disk protection program is not installed, system initialization 
continues with the loading of the operating system and the program components of the access 
control program, however, the protection provided by the hard disk protection program is not 
available. Control is then transferred to the operating system. Thereafter, the access control 
program intercepts interrupt service calls and verifies whether the user is authorized to access the 
requested resource.'). 

As per claim 16, Pereira teaches a method further comprising loading the attributes from a global 
set to the local set where the control resource is not found in the local set (col. 12 lines 13-59) (If 
the hard disk protection program is not installed, system initialization continues with the loading 
of the operating system and the program components of the access control program, however, the 
protection provided by the hard disk protection program is not available. Control is then 
transferred to the operating system. Thereafter, the access control program intercepts interrupt 
service calls and verifies whether the user is authorized to access the requested resource.') 

As per claim 17, Pereira teaches a method further comprising determining, after the resource is 
found in the local set or loaded into the local set, whether the identification number of the control 
resource is still active (col. 7 lines 19-49, col. 8 lines 1-30) ('Part of the installation procedure is 
to insert commands into a system initialization file, such as the AUTOEXEC.BAT file, before 
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the command which activates an operating system or Windows interface program. ')(' As shown 
in FIG. 3, the folder includes a window for the user's name (70) and a private directory (window 
72) for the user, if one has been identified by the Primary User. The folder preferably includes 
five tabs which identify the authorized resources for a user.') 

As per claim 18 Pereira teaches a method further comprising registering the resource when first 
introducing it to the operating system, (col. 7 lines 19-67) ('After the access control program is 
installed, the program requests the user to register as the Primary User and to identify a 
password. This password is used to identify the Primary User at subsequent logins. After 
installation of the program and registration of the Primary User, only the Primary User may 
thereafter install software on the PC, upgrade the access control program or uninstall the access 
program. ') 

As per claim 19, Pereira teaches a method wherein registration comprises: loading and 
initializing the module containing the resource control, storing certain control values for the 
module, executing custom functions for the model, obtaining an identification number for the 
control resource, and placing the new resource control in the global set (col. 12 lines 13-59) 
('Control is transferred to the operating system and the program components of the access 
control program limit user access to the resources identified in restricted lists as set forth above. 5 ) 
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Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Nilesh R Shah whose telephone number is 703-305-8105. The 
examiner can normally be reached on Monday-Friday 8am-4pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Meng An can be reached on 703-305-9678. The fax phone number for the 
organization where this application or proceeding is assigned is (703) 872-9306. 

Any inquiry of a general nature or relating to the status of this application or proceeding 
should be directed to the receptionist whose telephone number is 703-305-3900. 
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